In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
Details
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
Statement
Subscribe to updates
Product 1
Loading products...
No products found
Loading...
No matches
Unsubscribe
Enter your email and we'll send you a link to manage your subscription preferences.
Check your inbox
If this email is subscribed, we've sent a link to manage your preferences.
Contact us
Message Delivered!
Thanks for reaching out!
The TuxCare team has received your message and will get back to you shortly.